CVE-2025-9286
🟠 Łataj w tym tygodniu
Brak autoryzacji w wtyczce Appy Pie Connect dla WooCommerce pozwala na eskalację uprawnień.
CVSS
9.8
EPSS
0.5%
Exploit
none
Vendor
Opis źródłowy (NVD)
The Appy Pie Connect for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within the reset_user_password() REST handler in all versions up to, and including, 1.1.2. This makes it possible for unauthenticated attackers to to reset the password of arbitrary users, including administrators, thereby gaining administrative access.
privilege-escalation
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.5% |
| Opublikowano (NVD) | 2025-10-03 12:15:47 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-30 23:10:00 UTC |
Referencje
- https://plugins.trac.wordpress.org/browser/appy-pie-connect-for-woocommerce/trunk/connect-woocommerce-rest-api.php ([email protected])
- https://plugins.trac.wordpress.org/changeset/3385150/ ([email protected])
- https://wordpress.org/plugins/appy-pie-connect-for-woocommerce/ ([email protected])
- https://www.wordfence.com/threat-intel/vulnerabilities/id/36fb5b8d-1ea4-45c2-8639-b229efdb57db?source=cve ([email protected])